Get Real 300-620 Exam Dumps [Jan-2023] Practice Tests
Last 300-620 practice test reviews: Practice Test Cisco dumps
NEW QUESTION 51
Refer to the exhibit.
An engineer is integrating a VMware vCenter with Cisco ACI VMM domain configuration. ACI creates port-group names with the format of "Tenant | Application | EPG". Which configuration option is used to generate port groups with names formatted as "Tenant=Application=EPG"?
- A. virtual switch name
- B. enable tag collection
- C. security domains
- D. delimiter
Answer: D
NEW QUESTION 52
An engineer must deploy Cisco ACI across 10 geographically separated data centers. Which ACI site deployment feature enables the engineer to control which bridge domains contain Layer 2 flooding?
- A. Stretched Fabric
- B. Multi-Site
- C. GOLF
- D. Multi-Pod
Answer: B
NEW QUESTION 53
Which two components are essential parts of a Cisco ACI Virtual Machine Manager (VMM) domain policy configuration? (Choose two.)
- A. EPG static port binding
- B. VMM domain profile
- C. EPG association
- D. Layer 3 outside interface association
- E. IP address pool association
Answer: B,C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamenta
NEW QUESTION 54
Which method does the Cisco ACI fabric use to load-balance multidestination traffic?
- A. shortest-path trees
- B. PIM routing
- C. forwarding tag trees
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_010010.html
- D. spanning trees
Answer: C
NEW QUESTION 55
Which attribute should be configured for each user to enable RADIUS for external authentication in Cisco ACI?
- A. cisco-security domain
- B. cisco-av-pair
- C. cisco-aci-role
- D. cisco-auth-features
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/2-x/Security_config/ b_Cisco_APIC_Security_Configuration_Guide/b_Cisco_APIC_Security_Guide_chapter_01011.html
NEW QUESTION 56
A network engineer must allow secure access to the Cisco ACl out-of-band (OOB) management only from external subnets 10 0 0024 and 192.168 20 G'25. Which configuration set accomplishes this goal?
- A. Option B
- B. Option A
- C. Option C
- D. Option D
Answer: C
NEW QUESTION 57
Refer to the exhibit.
An engineer configures the Cisco ACI fabric for VMM integration with ESXi servers that are to be connected to the ACI leaves. The server team requires the network switches to initiate the LACP negotiation as opposed to the servers. The LAG group consists of two 10 Gigabit Ethernet links. The server learn also wants to evenly distribute traffic across all available links. Which two enhanced LAG policies meet these requirements? (Choose two.)
- A. LB Mode: Source and Destination MAC Address
- B. LB Mode: Destination IP Address and TCP/UDP Port
- C. LACP Mode: LACP Standby
- D. LB Mode: Source IP Address and TCP/UDP Port
- E. LACP Mode: LACP Active
Answer: A,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/aci_virtual_edge/configuration/2-x/Cisco-ACIVirtual- Edge-Configuration-Guide-202/Cisco-ACI-Virtual-Edge-Configuration-Guide-202_chapter_0100.html
NEW QUESTION 58
Which new construct must a user create when configuring in-band management?
- A. bridge domain
- B. VLAN pool
- C. management contract
- D. management tenant
Answer: A
Explanation:
Section: ACI Management
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/kb/ b_KB_Configuring_Static_Management_Access.html
NEW QUESTION 59
Refer to the exhibit.
Which Adjacency Type value should be set when the client endpoint and the service node interface are in a different subnet?
- A. L3Out
- B. Routed
- C. Unicast
- D. L3
Answer: D
NEW QUESTION 60
Refer to the exhibit.
Which two components should be configured as route reflectors in the ACI fabric? (Choose two.)
- A. Spine2
- B. apic2
- C. apic1
- D. Leaf1
- E. Leaf2
- F. Spine1
Answer: A,F
NEW QUESTION 61
A network engineer must integrate VMware vCenter cluster with Cisco ACI. The requirement is for the management traffic of the hypervisors and VM controllers to use the virtual switch associated with the Cisco Application Policy. The EPG called "Vmware-MGMT" with VLAN 300 has been created for this purpose. Which set of steps must be taken to complete the configuration?
- A. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
Create a static binding in the target EPG toward VMware hypervisors with VLAN 300, untagged access VLAN, and Untagged 802.1P mode. - B. Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
Associate the target EPG with the VMM domain with default settings. - C. Add VLAN 300 with static allocation to the VLAN POOL that is used for VMM integration.
Attach the VMM domain to the target EPG with resolution preprovision, mode static, untagged access VLAN, and Port-Encap 300. - D. Associate the target EPG with the VMM domain with default settings.
Enable Infrastructure VLAN on AAEP used toward VMware hypervisors.
Answer: C
NEW QUESTION 62
Refer to the exhibit.
A Cisco ACI fabric is newly deployed, and the security team requires more visibility of all inter-EPG traffic flows. All traffic in a VRF must be forwarded to an existing firewall pair. During fallover, the standby firewall must continue to use the same IP and MAC as the primary firewall. Drag and drop the steps from the left Into the Implementation order on the right to configure the service graph that meets the requirements. (Not all steps are used.)
Answer:
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/L4-L7_Services_Deployment/guide/b
* Create a service bridge domain and a layer 4 to layer 7 device within one cluster interface.
NEW QUESTION 63
An engineer needs to deploy a leaf access port policy group in ACI Fabric to support the following requirements:
* Control the amount of application data flowing into the system
* Allow the newly connected device to auto-negotiate link speed with the leaf switch Which two ACI policies must be configured to achieve these requirements? (Choose two.)
- A. L2 interface policy
- B. ingress control plane policing policy
- C. slow drain policy
- D. link level policy
- E. ingress data plane policing policy
Answer: D,E
Explanation:
Explanation
Slow Drain handles FCoE packets that are causing traffic congestion on ACI fabric. So, it is wrong.
Ingress control plane is wrong, because the request is for "application data flowing".
L2 interface policy is concerned about QinQ and VLAN scope.
NEW QUESTION 64
An engineer is extending EPG connectivity to an external network. The external network houses the Layer 3 gateway and other end hosts. Which ACI bridge domain configuration should be used?
- A. Forwarding: Custom
L2 Unknown Unicast: Hardware Proxy L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Enabled - B. Forwarding: Custom
L2 Unknown Unicast: Flood
L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Disabled - C. Forwarding: Custom
L2 Unknown Unicast: Flood
L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Enabled - D. Forwarding: Custom
L2 Unknown Unicast: Hardware Proxy L3 Unknown Multicast Flooding: Flood Multi Destination Flooding: Flood in BD ARP Flooding: Disabled
Answer: B
NEW QUESTION 65
Which method does the Cisco ACI fabric use to load-balance multidestination traffic?
- A. shortest-path trees
- B. forwarding tag trees
- C. PIM routing
- D. spanning trees
Answer: B
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamenta
NEW QUESTION 66
Drag and drop the Cisco ACI Layer 4 to Layer 7 service insertion terms on the left to the correct descriptions on the right.
Answer:
Explanation:
NEW QUESTION 67
The company ESXi infrastructure is hosted on the Cisco UCS-B Blade Servers. The company decided to take advantage of ACI VMM integration to enable consistent enforcement of policies across virtual and physical workloads. The requirement is to prevent the packet loss between the distributed virtual switch and the ACI fabric. Which setting must be implemented on a vSwitch policy to accomplish this goal?
- A. MAC Pinning
- B. Static Channel
- C. LLDP
- D. LACP
Answer: A
NEW QUESTION 68
Refer to the exhibit.
Refer to the exhibit A Cisco ACI fabric is using out-of-band management connectivity The APIC must access a routable host with an IP address of 192 168 11 2 Which action accomplishes this goal?
- A. Modify the Pod Profile to use the default Management Access Policy
- B. Change the switch APIC Connectivity Preference to in-band management
- C. Add a Fabric Access Policy to allow management connections.
- D. Remove the in-band management address from the APIC.
Answer: D
NEW QUESTION 69
Which table holds IP address, MAC address and VXLAN/VLAN information on a Cisco ACI leaf?
- A. endpoint
- B. adjacency
- C. ARP
- D. RIB
Answer: A
Explanation:
Section: ACI Fabric Infrastructure
Explanation/Reference: https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric- infrastructure/white-paper-c11-739989.html
NEW QUESTION 70
A Cisco ACI is integrated with a VMware vSphere environment. The port groups must be created automatically in vSphere and propagated to hypervisors when created in the ACI environment. Which action accomplishes this goal?
- A. Associate the VMM domain with the EPGs that must be available in vCenter.
- B. Configure contracts for the EPGs that are required on the ESXi hosts.
- C. Create the port groups on the vCenter that reflect the EPG names in the APIC.
- D. Assign the uplinks of the ESXi hosts to the vDS that the APIC created.
Answer: A
NEW QUESTION 71
Which Cisco APIC configuration prevents a remote network that is not configured on the bridge domain from being learned by the fabric?
- A. enable IP Data-plane Learning
- B. enable Unicast Routing
- C. enable ARP Flooding to BD
- D. enable Limit IP Learning to Subnet
Answer: D
Explanation:
Section: ACI Fabric Infrastructure
Explanation/Reference:
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/ white-paper-c11-739989.html
NEW QUESTION 72
An engineer must configure RADIUS authentication with Cisco ACI for remote authentication with out-of-band management access. Drag and drop the RADIUS configuration steps from the left into the required implementation order on the right. Not all steps are used.
Answer:
Explanation:
NEW QUESTION 73
......
Get Ready to Pass the 300-620 exam with Cisco Latest Practice Exam : https://www.testsimulate.com/300-620-study-materials.html